Privacy Policy

Last updated: May 25, 2026

1. Introduction

Welcome to StarsBots (“we,” “our,” or “us”). We are committed to protecting your privacy and ensuring you have a positive experience on our website and in using our products and services.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us through integrated third-party platforms including Meta platforms (WhatsApp, Instagram, and Facebook Messenger). Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site.

2. Information We Collect

2.1 Information You Provide

We collect information that you provide directly to us, including:

  • Name and contact information (email address, phone number)
  • Account credentials (username, password)
  • Payment information (processed securely through third-party payment processors)
  • Business information (company name, industry, size)
  • Communications with us (support requests, feedback)

2.2 Automatically Collected Information

When you use our services, we automatically collect certain information, including:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages visited, time spent, features used)
  • Cookies and similar tracking technologies
  • Log files and analytics data

2.3 Data Collected Through Meta Platforms

When you or your end-users interact with chatbots you create on StarsBots via Meta platforms (WhatsApp Business, Instagram Direct, or Facebook Messenger), we collect and process the following categories of data through Meta’s APIs:

  • Message content: Text messages, media files (images, audio, documents), and interactive message responses exchanged within chatbot conversations
  • Sender identifiers: WhatsApp phone numbers, Instagram user IDs, and Facebook Page-scoped user IDs provided by Meta’s platform
  • Profile information: Display names and profile details made available by Meta’s Graph API within the permitted scope of granted permissions
  • Conversation metadata: Message timestamps, delivery status, message IDs, and thread identifiers
  • Page and account data: Facebook Page names and IDs, Instagram Business Account IDs, and WhatsApp Business Account phone number IDs connected by our platform users (chatbot operators)

This data is collected solely for the purpose of enabling chatbot functionality — delivering automated AI responses, routing conversations to human agents, and storing conversation history accessible to the chatbot operator.

We do not use Meta platform data to serve advertisements, build advertising profiles, or share end-user data with advertising networks or data brokers.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our chatbot automation services
  • To process and store conversation messages from connected Meta channels on behalf of chatbot operators
  • To generate AI-powered responses to end-user messages via integrated AI models
  • To process transactions and send related information
  • To send technical notices, updates, and support messages
  • To respond to comments, questions, and requests
  • To monitor and analyze trends, usage, and activities in aggregated, anonymized form
  • To detect, prevent, and address technical issues or policy violations
  • To comply with applicable laws, Meta Platform Policies, and legal obligations

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information or end-user conversation data to third parties. We may share information only in the following circumstances:

  • Service Providers: We may share information with trusted third-party service providers who perform services on our behalf, such as payment processing (Stripe), cloud hosting, database storage, and AI inference services (OpenAI, Google Gemini). These providers are bound by contractual data processing agreements.
  • Meta Platforms, Inc.: When you connect Meta channels (WhatsApp, Instagram, Messenger), data is transmitted to and from Meta’s servers via their Graph API under Meta’s own Privacy Policy and Platform Terms. We act as a data processor on behalf of chatbot operators in this context.
  • Communication Providers: SMS messages are routed through Twilio, Inc. Transactional and notification emails may be routed through SendGrid (Twilio). These providers process message content solely for delivery.
  • Legal Requirements: We may disclose information if required by law, court order, or in response to valid requests by public authorities.
  • Business Transfers: In the event of a merger, acquisition, or sale of all or substantially all assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
  • With Your Consent: We may share information for any other purpose with your explicit prior consent.

Data received from Meta APIs is not shared with third parties beyond what is strictly necessary to provide the requested service to the chatbot operator, and is never used for advertising targeting.

5. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using TLS/HTTPS
  • Encrypted storage of sensitive credentials (access tokens, API keys)
  • Role-based access controls limiting data access to authorized personnel
  • Regular security reviews and dependency updates
  • Webhook signature verification for all incoming Meta platform events

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

6. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

  • Access: The right to access and receive a copy of your personal data
  • Rectification: The right to correct inaccurate or incomplete data
  • Erasure (Right to be Forgotten): The right to request deletion of your personal data, including conversation history collected through Meta channels
  • Restriction: The right to restrict or object to the processing of your data
  • Portability: The right to receive your data in a structured, machine-readable format
  • Withdraw Consent: The right to withdraw consent at any time where processing is based on consent
  • Opt-Out: Chatbot operators may disconnect their Meta channel integrations at any time, which stops future data collection from those channels

To exercise any of these rights, please contact us using the information in Section 13. We will respond to verified requests within 30 days.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to maintain sessions and improve our service. You may instruct your browser to refuse all cookies or alert you when cookies are being sent. Disabling cookies may affect your ability to use certain features of the Service.

  • Authentication and session management
  • Remembering your preferences and settings
  • Analyzing website traffic and usage patterns (aggregated and anonymized)

8. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law:

  • Account data: Retained for the duration of your account and deleted within 90 days of account closure upon request
  • Conversation history (all channels): Retained while your account is active. Operators may delete individual conversations at any time from the dashboard. All conversation data is deleted within 90 days of account termination upon request.
  • Meta platform access tokens: Retained until the chatbot operator disconnects the channel, at which point tokens are cleared from our database
  • Payment records: Retained for 7 years as required by financial regulations
  • Server logs: Retained for up to 90 days for security and debugging purposes, then automatically deleted

To request deletion of your data or conversation history, please contact us at the address in Section 13.

9. Meta Platform Data & Third-Party Channel Integrations

9.1 Scope of Meta Data Use

StarsBots integrates with Meta Platforms, Inc. (“Meta”) to enable WhatsApp Business, Instagram Direct, and Facebook Messenger chatbot functionality. Our use of data obtained through Meta’s APIs strictly complies with the Meta Platform Terms and Meta Developer Policies.

9.2 Permitted Uses of Meta Data

Data obtained via Meta APIs is used exclusively to:

  • Receive and display inbound messages in the operator’s conversation dashboard
  • Generate and deliver AI-powered automated replies on behalf of the chatbot operator
  • Store conversation history for the chatbot operator’s review and management
  • Route conversations to human agents within the operator’s team

9.3 Prohibited Uses

In compliance with Meta Platform Policies, we do not and will not:

  • Sell, license, or purchase Meta user data
  • Use Meta data to build advertising profiles or target users with ads
  • Share Meta user data with data brokers or ad networks
  • Store Meta data beyond what is necessary to provide the service
  • Use Meta platform data to surveil users or monitor individuals without their knowledge

9.4 Data Deletion Requests from Meta Users

End-users who have interacted with a chatbot via a Meta platform may request deletion of their conversation data. Such requests should be submitted to the chatbot operator or directly to us at the contact address in Section 13. We will process verified deletion requests within 30 days.

Additionally, in compliance with Meta’s data deletion requirements, we support a data deletion callback endpoint. Meta users may request data deletion by visiting Facebook’s privacy settings. Upon receiving a deletion signal from Meta, we will delete all conversation data associated with that user identifier within 30 days and provide a confirmation URL.

10. GDPR & International Data Protection

10.1 Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, our processing of your personal data is based on:

  • Contract performance: Processing necessary to provide the Service under our Terms of Service
  • Legitimate interests: Processing for fraud prevention, service improvement, and security
  • Legal obligation: Processing required to comply with applicable laws
  • Consent: Where you have given explicit consent (e.g., marketing communications)

10.2 International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our servers and service providers are located. Where required, such transfers are governed by appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission.

10.3 Your EEA/UK Rights

In addition to the rights listed in Section 6, EEA and UK residents have the right to lodge a complaint with their local data protection authority (e.g., the ICO in the UK or a supervisory authority in an EU member state).

10.4 Data Protection Officer

For GDPR-related inquiries, please contact us using the information provided in Section 13. We will acknowledge your inquiry within 72 hours.

11. Children’s Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will take steps to remove such information from our systems.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. For significant changes, we will also notify registered users by email. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about our data practices, please contact us:

Email: support@starsbots.com

Address: Delaware Dover, 1111b South Governors Avenue

Ready to transform your support?

Start free — no credit card required. Deploy your AI agent in minutes.

Get Started Free
StarsBots
StarsBots

StarsBots: Next-gen AI platform powered by Gemini & OpenAI. Automate customer support in 100+ languages with smart chatbots.Scale your business 24/7 with ease.

Connect With Us

Follow us on social media for updates, news, and insights.

© 2026 StarsBots. Powered by Pronto Intervento LLC.

Privacy PolicyTerms of Service